Matomo

Building security for M&A solutions: 5-years of SSDLC | Cossack Labs
Case studies
Building security for M&A solutions: 5-years of SSDLC

Building security for M&A solutions: 5-years of SSDLC

2019 - 2024 SaaS Virtual Data Room Cloud data security
Building security for M&A solutions: 5-years of SSDLC

Overview

Industry

  • M&A SaaS provider
  • VDR
  • Diligence and productivity software

Technology stack

  • iOS, Android native apps
  • React Native mobile apps
  • GraphQL, REST and Java backend

Regulations

  • CCPA, GDPR, HIPAA
  • Internal security policies
  • Encryption Export Regulations

Challenges

[01]

Proactive security posture management

Having recognised the limitations of annual pentests, the client realised the need for a dedicated application security team able to design and build product security together with their product team.

[02]

Security development processes should be easy to follow

The need for well-documented security processes to ensure consistent application and efficient knowledge transfer. The security processes are to be simple, logical, nicely described and stable so that new engineers could nicely adopt them.

[03]

Shifting mobile applications from native to React Native

Security should be suitable for the new technological stack. The development team should adapt security strategies to the specifics of React Native, as well as incorporate additional robust security measures, tailored to the nuances of cross-platform framework.

Technology requirements

Technology requirements

Long-term mitigation strategy

The mobile application requires appropriate security controls and issues mitigation, considering iOS, Android and React Native threats. Adaptability and maintainability are crucial to avoid security regressions.

Flexible security architecture

Scaling and evolving security architecture, capable to meet their objectives and keep pace with the company’s development. The product is being continuously upgraded to meet the organisation's growth.

Security tailored to product goals

Leveraging client feedback to prioritise and adjust security controls, equip teams for seamless integration with the client’s standards to meet their expectations.

Our approach

Tailored SSDLC process

Applying security best practices to each development phase: security architecture review, designing and building complex security controls, secure code review of implemented changes, security testing, regression testing, creating scripts for CI/CD pipeline to automate security validation, security review of production configuration, and many more.

Measurable security

We are using a security verification standard—an extended, supplemented and project-tailored version of OWASP MASVS—to measure product security posture and calculate a “security score”. It makes security tangible and comparable, tracking how new features and other changes impact project security.

Continuous monitoring of new threats and risks

Our team keeps the developers informed about the latest state-of-the-art security controls. We keep monitoring for the newest vulnerabilities and CVEs relevant to the platform, ensuring that the product team is always equipped with the most current and effective security measures.
Our approach

Solution

Application security expertise

Providing security guidance on complex features

An example of one of the sections in security regression checklist that is completed in for each release
An example of one of the sections in security regression checklist that is completed in for each release

Security processes

A screenshot from our lecture about dependency management recommendations for React Native libraries.
A screenshot from our lecture about dependency management recommendations for React Native libraries.

Assistance in dependencies management process

The number of security issues in open and done state for the last 3 years showing that security evolves together with the product functionality
The number of security issues in open and done state for the last 3 years showing that security evolves together with the product functionality

Collaborating as an internal security team

Results and outcomes

Shifted security efforts from firefighting to proactive work
We managed to make security a seamless part of the workflow, fostering clear communication between product and development teams. We enabled transition from reactive "firefighting" to a proactive security posture, while simplifying security processes and making them well-documented, simple, stable, and logical.

Making security less frustrating for the product team
We led and maintained SSDLC and security processes the [REDACTED] company didn’t have at the very beginning of our cooperation. By regularly providing knowledge base and expert assistance for development and QA teams, we enhanced cooperation within the teams. We tailored security to product goals and clients’ expectations, maintained flexible security architecture and enhanced security posture of our client’s platform.

Stable 80% security score for 2 years
Stable security score and not growing backlog are the achievements of our long and fruitful cooperation with the client. Measurable results and the ability to track them through the years helps in defining the security roadmap of the product and enhance security even further. As a result, no issues were found during recent external penetration testing, making our client satisfied with our cooperation.

Client satisfaction via enhanced security
From now on our client’s platform has all the security controls that their customers typically require. So when our client receive security questionnaires and RFIs, they can provide clear and thorough answers promptly. Thus our client gets satisfied customers and we get a satisfied client.

Contributing to evidence-based reputation on the market
As of today, our client has a well-educated team, timely and effectively managing all security processes. Stable strong security posture, proactive security approach, little-to-no emergency situations, smooth and well-managed security processes make our client and their software platform attractive on the market.


Up next

Got a challenge that's still standing?

Let’s start a conversation.

Start a conversation

Get whitepaper

Apply for the position

Our team will review your resume and provide feedback
within 5 business days

Thank you!
We’ve received your request and will respond soon.
Your resume has been sent!
Our team will review your resume and provide feedback
within 5 business days